This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
Summary
A new Windows malware named CLOSEDQUORUM has been discovered that utilizes up to four AI models to vote on its next malicious actions, bypassing traditional attacker command and control servers. These AI models can direct the malware to steal sensitive data like credentials, browser passwords, and crypto wallet information. Cisco Talos has not yet observed this malware fully operational, and the publicly available version is not functional.
IFF Assessment
The development of malware that uses AI to make autonomous decisions about its targets and actions represents a significant advancement in offensive capabilities, posing a greater threat to defenders.
Defender Context
The emergence of malware leveraging AI for decision-making highlights a critical trend where attackers are using advanced technologies to automate and potentially enhance their operations. Defenders need to be prepared for more sophisticated and adaptive threats that may evolve rapidly, requiring advancements in threat detection and response capabilities that can handle AI-driven malicious behavior.